[PATCH] libstdc++: Fix use-after-free in pbds binary heap (CVE-2026-102010) [PR127656]

Jonathan Wakely jwakely@redhat.com
Tue Sep 29 10:57:00 GMT 2026


After reallocating the storage the m_a_entries pointer is left dangling
and the new storage is leaked.

libstdc++-v3/ChangeLog:

	PR libstdc++/127656
	* include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
	(erase_if): Update m_a_entries after reallocation.
	* testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc:
	New test.
---

Tested x86_64-linux.

Backports needed too. Then we should delete the pb_ds stuff from trunk.

 .../detail/binary_heap_/erase_fn_imps.hpp     |  1 +
 .../regression/priority_queues_erase_if.cc    | 19 +++++++++++++++++++
 2 files changed, 20 insertions(+)
 create mode 100644 libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc

diff --git a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
index 2e70ed5c663d..80d2cccbbf0b 100644
--- a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
+++ b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
@@ -121,6 +121,7 @@ erase_if(Pred pred)
       entry_pointer new_entries = s_entry_allocator.allocate(new_size);
       std::copy(m_a_entries, m_a_entries + left, new_entries);
       s_entry_allocator.deallocate(m_a_entries, m_actual_size);
+      m_a_entries = new_entries;
       m_actual_size = new_size;
       resize_policy::notify_arbitrary(m_actual_size);
     }
diff --git a/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
new file mode 100644
index 000000000000..30b8452eff96
--- /dev/null
+++ b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
@@ -0,0 +1,19 @@
+// { dg-do run }
+
+// CVE-2026-201020 use-after-free in binary heap erase_if
+
+#include <ext/pb_ds/priority_queue.hpp>
+
+bool is_odd(int v) { return v & 1; }
+
+int main()
+{
+  using __gnu_pbds::priority_queue;
+  using __gnu_pbds::binary_heap_tag;
+  priority_queue<int, std::less<int>, binary_heap_tag> q;
+  q.push(1);
+  q.push(2);
+  q.push(3);
+  q.erase_if(&is_odd);
+  q.clear();
+}
-- 
2.55.0



More information about the Libstdc++ mailing list